Hacker News new | ask | show | jobs
by mikeash 4818 days ago
I felt sorry for the guy up to this point. You have the notoriously insecure Java plugin enabled in the same browser you use to access your digital cash, and you click on random links in a chat full of people with accounts on the same digital cash site? No, that's your fault, not Mtgox's.

He goes on to say, "First because their site is not secured against such rudimentary attacks as has been demonstrated today." I can't fathom how they're supposed to protect from users' computers being taken over. The only real way to do that is to have two-factor authentication... which they offer, and this guy did not use.

It sucks to get robbed, certainly. But blaming Mtgox for this is uncalled-for.

1 comments

Does Mt Gox require you to enable client-side Java?

I don't like running Java on my computers even if they don't have access to $10,000 worth of bitcoins.

No.

In fact, I use a curses based program alongside the Mt.Gox API.

I had to log in at one point, obviously, but I can handle it all using the API now.

For those interested : https://github.com/prof7bit/goxtool